A Qualitative Study of Adoption Barriers and Challenges for Passwordless Authentication in German Public Administrations
Jan-Ulrich Holtgrave, Sabrina Klivan, Karola Marky, Sascha Fahl
Abstract
Public administrations provide critical services and manage sensitive data for a country’s citizens. Recent phishing campaigns targeting public sector employees highlight their attractiveness as targets. Deploying state-of-the-art authentication technologies, such as FIDO2, can improve overall security. We conducted a mixed-methods study in Germany to understand better the practices and challenges of deploying passwordless authentication in the public sector. First, we conducted an online survey (N=108) among German public sector employees to gain insights into their experiences and challenges. Next, we partnered with an e-government vendor and performed an in-situ experiment. We let 11 employees from the public sector experience FIDO2 under real-world conditions. Our results show that only a minority of our participants were aware of current passwordless authentication procedures. In our experiment, FIDO2-based methods left an overall positive impression. Hierarchical and heterogeneous public sector structures and the need for more technical expertise and equipment were barriers to adoption.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers2
- The State's Politics of "Fake Data"Chuncheng Liu, danah boydCHI 2026
- The State of Passkeys: Studying the Adoption and Security of Passkeys on the WebLouis Jannett, Andreas Mayer, Maximilian Westers, Vladislav Mladenov et al.USENIX Security 2026
Builds on9
- Data Breaches, Phishing, or Malware?: Understanding the Risks of Stolen CredentialsKurt Thomas, Frank Li, Ali Zand, Jacob Barrett et al.CCS 2017 · 248 citations
- Is FIDO2 the Kingslayer of User Authentication? A Comparative Usability Study of FIDO2 Passwordless AuthenticationSanam Ghorbani Lyastani, Michael Schilling, Michaela Neumayr, Michael Backes et al.S&P 2020 · 124 citations
- A Tale of Two Studies: The Best and Worst of YubiKey UsabilityJoshua Reynolds, Trevor Smith, Ken Reese, Luke Dickinson et al.S&P 2018 · 95 citations
- "It's Stored, Hopefully, on an Encrypted Server": Mitigating Users' Misconceptions About FIDO2 Biometric WebAuthnLeona Lassak, Annika Hildebrandt, Maximilian Golla, Blase UrUSENIX Security 2021 · 48 citations
- Why Aren't We Using Passkeys? Obstacles Companies Face Deploying FIDO2 Passwordless AuthenticationLeona Lassak, Elleen Pan, Blase Ur, Maximilian GollaUSENIX Security 2024 · 35 citations
Related papers
- FIDO2 the Rescue? Platform vs. Roaming Authentication on SmartphonesLeon Würsching, Florentin Putz, Steffen Haesler, Matthias HollickCHI 2023 · 15 citations
- Evaluating the Security Posture of Real-World FIDO2 DeploymentsDhruv Kuchhal, Muhammad Saad, Adam Oest, Frank LiCCS 2023 · 13 citations
- The Passkey Promise: A Comparative Usability Study of MFA MethodsErwin Kupris, Thomas SchreckS&P 2026
- Breaching Security Keys without Root: FIDO2 Deception Attacks via Overlays exploiting Limited Display AuthenticatorsAhmed Tanvir Mahdad, Mohammed Jubur, Nitesh SaxenaCCS 2024 · 3 citations
- Fast IDentity Online with Anonymous Credentials (FIDO-AC)Wei-Zhu Yeoh, Michal Kepkowski, Gunnar Heide, Dali Kaafar et al.USENIX Security 2023
